Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 26, 2026, 10:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
233181 5 警告 phpBB - phpBB の search 関数における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2008-4125 2012-12-20 18:52 2008-09-18 Show GitHub Exploit DB Packet Storm
233182 7.8 危険 サン・マイクロシステムズ - SunMC の PRM モジュールにおけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2008-4117 2012-12-20 18:52 2008-09-15 Show GitHub Exploit DB Packet Storm
233183 5 警告 talkback - TalkBack における設定情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2008-4115 2012-12-20 18:52 2008-09-16 Show GitHub Exploit DB Packet Storm
233184 7.2 危険 Python Software Foundation - Python の Tools/faqwiz/move-faqwiz.sh における任意のファイルを上書きされる脆弱性 CWE-59
リンク解釈の問題
CVE-2008-4108 2012-12-20 18:52 2008-09-18 Show GitHub Exploit DB Packet Storm
233185 5.1 警告 WordPress.org - WordPress におけるユーザパスワードを任意の値に変更される脆弱性 CWE-20
不適切な入力確認
CVE-2008-4106 2012-12-20 18:52 2008-09-8 Show GitHub Exploit DB Packet Storm
233186 8.5 危険 The phpMyAdmin Project - phpMyAdmin の libraries/database_interface.lib.php における任意のコードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2008-4096 2012-12-20 18:52 2008-09-15 Show GitHub Exploit DB Packet Storm
233187 7.5 危険 Ruby on Rails project - Ruby on Rails における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-4094 2012-12-20 18:52 2008-09-30 Show GitHub Exploit DB Packet Storm
233188 6.8 警告 yourownbux - YourOwnBux の memberstats.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-4093 2012-12-20 18:52 2008-09-15 Show GitHub Exploit DB Packet Storm
233189 6.8 警告 source workshop - Web Directory Script の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-4091 2012-12-20 18:52 2008-09-15 Show GitHub Exploit DB Packet Storm
233190 7.5 危険 source workshop - Reciprocal Links Manager の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-4086 2012-12-20 18:52 2008-09-15 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 26, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
294331 - hp service_manager Cross-site scripting (XSS) vulnerability in the Mobility Web Client and Service Request Catalog (SRC) components in HP Service Manager (SM) 7.21 and 9.x before 9.34 allows remote attackers to inject … CWE-79
Cross-site Scripting
CVE-2013-6222 2024-11-21 10:58 2014-08-24 Show GitHub Exploit DB Packet Storm
294332 - ibm power_760_firmware
power_770
power_780
power_795
power_ese
power_740_firmware
power_710
power_720
power_730
power_740
power_770_firmware
power_750
power_760
pow…
Unspecified vulnerability on IBM Power 7 Systems 740 before 740.70 01Ax740_121, 760 before 760.40 Ax760_078, and 770 before 770.30 01Ax770_062 allows local users to gain Service Processor privileges … NVD-CWE-noinfo
CVE-2013-6306 2024-11-21 10:58 2014-08-23 Show GitHub Exploit DB Packet Storm
294333 - yealink sip-t38g cgi-bin/cgiServer.exx in Yealink VoIP Phone SIP-T38G allows remote authenticated users to execute arbitrary commands by calling the system method in the body of a request, as demonstrated by running … CWE-78
OS Command 
CVE-2013-5758 2024-11-21 10:58 2014-08-4 Show GitHub Exploit DB Packet Storm
294334 - yealink sip-t38g Absolute path traversal vulnerability in Yealink VoIP Phone SIP-T38G allows remote authenticated users to read arbitrary files via a full pathname in the dumpConfigFile function in the command parame… CWE-22
Path Traversal
CVE-2013-5757 2024-11-21 10:58 2014-08-4 Show GitHub Exploit DB Packet Storm
294335 - yealink sip-t38g Directory traversal vulnerability in Yealink VoIP Phone SIP-T38G allows remote authenticated users to read arbitrary files via a .. (dot dot) in the page parameter to cgi-bin/cgiServer.exx. CWE-22
Path Traversal
CVE-2013-5756 2024-11-21 10:58 2014-08-4 Show GitHub Exploit DB Packet Storm
294336 - oracle mojarra Oracle Mojarra 2.2.x before 2.2.6 and 2.1.x before 2.1.28 does not perform appropriate encoding when a (1) <h:outputText> tag or (2) EL expression is used after a scriptor style block, which allows r… CWE-79
Cross-site Scripting
CVE-2013-5855 2024-11-21 10:58 2014-07-17 Show GitHub Exploit DB Packet Storm
294337 - yealink sip-t38g config/.htpasswd in Yealink IP Phone SIP-T38G has a hardcoded password of (1) user (s7C9Cx.rLsWFA) for the user account, (2) admin (uoCbM.VEiKQto) for the admin account, and (3) var (jhl3iZAe./qXM) f… CWE-255
Credentials Management
CVE-2013-5755 2024-11-21 10:58 2014-07-16 Show GitHub Exploit DB Packet Storm
294338 - dahuasecurity dvr_firmware Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive information including user credentials, change user passwords, clear log files, and perfo… CWE-287
Improper Authentication
CVE-2013-6117 2024-11-21 10:58 2014-07-12 Show GitHub Exploit DB Packet Storm
294339 - ibm marketing_platform SQL injection vulnerability in IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. CWE-89
SQL Injection
CVE-2013-6311 2024-11-21 10:58 2014-06-28 Show GitHub Exploit DB Packet Storm
294340 - ibm marketing_platform Cross-site scripting (XSS) vulnerability in IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. CWE-79
Cross-site Scripting
CVE-2013-6310 2024-11-21 10:58 2014-06-28 Show GitHub Exploit DB Packet Storm